Subdomain takeover of ████.jitsi.net

Disclosed: 2021-05-14 17:35:31 By ian To 8x8
High
Vulnerability Details
## Summary █████.jitsi.net points to an AWS EC2 instance at 18.195.93.116 that no longer exists. I was able to take control of this IP address and run my own EC2 instance. I can now serve content on this domain, obtain a TLS certificate for this domain, etc. If any customers or servers are pointing to anything within this domain, I could serve them arbitrary/malicious content. I could also use this in case your domain whitelists your own domain for OAuth, or if there are cookies scoped to the entire domain. Usually this can have a high impact. ``` % dig +short ██████.jitsi.net 18.195.93.116 % curl ██████████.jitsi.net <!-- hackerone.com/ian --> ``` ## Impact Subdomain takeover
Actions
View on HackerOne
Report Stats
  • Report ID: 1197013
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report